5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26220
Spotfire Analyst Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

The Spotfire Library component of TIBCO Software Inc.'s Spotfire Analyst and Spotfire Server contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s Spotfire Analyst: versions 11.4.7 and below, versions 11.5.0, 11.6.0, 11.7.0, 11.8.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4, versions 12.1.0 and 12.1.1 and Spotfire Server:

CVE-2023-0146
Naver Map Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0490
f(x) TOC Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The f(x) TOC WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-48202
Software Genérico Web
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager component.

CVE-2023-3228
fossbilling/fossbilling General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.

CVE-2023-0559
GS Portfolio for Envato Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-5323
dolibarr/dolibarr Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.

CVE-2023-6485
Html5 Video Player Web Windows
5.4
MEDIUM
EPSS
1.9%
2023 1 PoC

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

CVE-2023-33962
jstachio Web
5.4
MEDIUM
EPSS
0.9%
2023 CWE-79 1 PoC

JStachio is a type-safe Java Mustache templating engine. Prior to version 1.0.1, JStachio fails to escape single quotes `'` in HTML, allowing an attacker to inject malicious code. This vulnerability can be exploited by an attacker to execute arbitrary JavaScript code in the context of other users visiting pages that use this template engine. This can lead to various consequences, including session hijacking, defacement of web pages, theft of sensitive information, or even the propagation of malware. Version 1.0.1 contains a patch for this issue. To mitigate this vulnerability, the template e

CVE-2023-0074
WP Social Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0271
WP Font Awesome Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43734
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-1905
WP Popups Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to an insufficient fix of CVE-2023-24003

CVE-2023-31548
Software Genérico Web ⚡ nuclei
5.4
MEDIUM
EPSS
19.2%
2023 1 PoC

A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-1883
thorsten/phpmyfaq Web
5.4
MEDIUM
EPSS
0.4%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-0252
Contextual Related Posts Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0282
YourChannel: Everything you want in a YouTube plugin. Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

CVE-2023-33677
Software Genérico Database
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

CVE-2023-43706
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "email_templates_key" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-30790
MonicaHQ General
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.